Lucene search

K
freebsdFreeBSD75F2382E-B586-11DD-95F9-00E0815B8DA8
HistoryNov 15, 2008 - 12:00 a.m.

syslog-ng2 -- startup directory leakage in the chroot environment

2008-11-1500:00:00
vuxml.freebsd.org
15

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

59.3%

Florian Grandel reports:

I have not had the time to analyze all of syslog-ng code.
But by reading the code section near the chroot call and looking
at strace results I believe that syslog-ng does not chdir to the
chroot jail’s location before chrooting into it.
This opens up ways to work around the chroot jail.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchsyslog-ng2< 2.0.9_2UNKNOWN
FreeBSDanynoarchsyslog-ng<= 1.6.12_1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

59.3%